Bayesian Stackelberg games for cyber-security decision support

Bayesian Stackelberg games for cyber-security decision support
复制标题

DOI:
10.1016/j.dss.2021.113599
复制
发表时间:
2021-05
期刊:
Decis. Support Syst.
影响因子:
--
通讯作者:
Yunxiao Zhang;P. Malacaria
Yunxiao Zhang;P. Malacaria
中科院分区:
其他
文献类型:
--
作者:
Yunxiao Zhang;P. Malacaria

文献摘要

相似文献

这里介绍了网络安全的决策支持系统。该系统旨在选择最佳的安全控制组合来抵御多阶段攻击。该系统有几个组成部分:预防性优化,用于选择初始防御组合的控制;学习机制,用于估计可能的持续攻击;以及在线优化,选择最佳组合来对抗持续攻击。该系统依赖于双层优化的有效解决方案,特别是,在线优化被证明是贝叶斯Stackelberg博弈解决方案。所提出的解决方案被证明比 Harsanyi 变换等经典解决方案和更新的高效求解器更有效。此外,与以前的方法相比,所提出的解决方案在减轻持续攻击方面提供了显着的安全改进。这里介绍的新技术依赖于混合整数圆锥规划(MICP)、强对偶性和完全幺模矩阵的最新进展。
A decision support system for cyber-security is here presented. The system aims to select an optimal portfolio of security controls to counteract multi-stage attacks. The system has several components: a preventive optimisation to select controls for an initial defensive portfolio, a learning mechanism to estimate possible ongoing attacks, and an online optimisation selecting an optimal portfolio to counteract ongoing attacks. The system relies on efficient solutions of bi-level optimisations, in particular, the online optimisation is shown to be a Bayesian Stackelberg game solution. The proposed solution is shown to be more efficient than both classical solutions like Harsanyi transformation and more recent efficient solvers. Moreover, the proposed solution provides significant security improvements on mitigating ongoing attacks compared to previous approaches. The novel techniques here introduced rely on recent advances in Mixed-Integer Conic Programming (MICP), strong duality and totally unimodular matrices.